A network security monitoring method and system based on dynamic vulnerability verification

By dynamically verifying vulnerability exploitability, the problem of resource allocation imbalance in network security monitoring is solved, the dynamic and robustness of vulnerability verification is achieved, and security and flexible response capabilities are improved.

CN120389908BActive Publication Date: 2025-09-02BEIJING TIANYUN NETWORK SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510872751.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-09-02
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

The existing network security monitoring technology lacks real-time dynamic verification of the true exploitability of vulnerabilities, resulting in an imbalance in the allocation of security resources and making it difficult to effectively deal with actual threats.

Method used

By collecting real-time network security monitoring data, identifying abnormal operation events, extracting thermal noise entropy values, generating dynamic random seeds, building isolated container instances, running security verification scripts, determining the exploitable status of vulnerabilities based on the consistency decision mechanism, and performing blocking and alarm operations.

Benefits of technology

The dynamic and non-deterministic vulnerability verification process is realized, the randomness and robustness of the verification process is enhanced, the evasion resistance and security are improved in complex network environments, and the flexible response ability of heterogeneous executor scheduling strategies is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389908B_ABST
    Figure CN120389908B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security monitoring method and system based on dynamic vulnerability verification, which relates to the field of network security technology. The method comprises the following steps: collecting a thermal noise signal as a physical entropy source based on suspicious event alarm data, calculating the fluctuation parameters of the Brownian motion trajectory time series through a Brownian motion trajectory modeling method, and extracting a thermal noise entropy value; hashing the thermal noise entropy value to generate a dynamic random seed, and performing mapping rule calculation based on the dynamic random seed and a preset heterogeneous executor mapping strategy rule to obtain a target executor sequence number; constructing an isolated container instance at an edge node through a container management interface based on the target executor sequence number, and inputting a vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain a security verification script. The present invention improves the flexible response capability and scheduling efficiency of the heterogeneous executor scheduling strategy in a variable task environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network security monitoring method and system based on dynamic vulnerability verification. Background Art

[0002] With the widespread deployment of information infrastructure and the rapid development of internet technology, network security risks are becoming increasingly covert, intelligent, and persistent. Traditional network security protection methods, such as signature-based intrusion detection systems (IDS), vulnerability scanning systems (VSS), and security information and event management platforms (SIEM), have become standard configurations for organizations to implement security measures. These methods often rely on attack signature libraries or historical vulnerability information for security situation analysis and alerting. When potential threats are discovered, they typically employ static rule-matching mechanisms to identify abnormal or suspicious communication behavior.

[0003] In existing network security monitoring mechanisms, vulnerability exploitability is typically determined based on static analysis or manual audit results, lacking dynamic correlation with actual operational behavior. This "speculative risk" approach often fails to reflect whether a vulnerability is truly exploitable in a specific context, leading to an imbalance in security resource allocation. This can lead to excessive protection measures for unexploitable vulnerabilities and delayed response to vulnerabilities that do have exploitable channels. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a network security monitoring method based on dynamic vulnerability verification to solve the problem that existing network security monitoring technology lacks real-time dynamic verification of the true exploitability of vulnerabilities.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0007] In the first aspect, the present invention provides a network security monitoring method based on dynamic vulnerability verification, which includes collecting real-time network security monitoring raw data, detecting abnormal operations through predefined attack behavior rules, identifying potential abnormal operation events, triggering alarm logic and generating suspicious event alarm data; based on the suspicious event alarm data, collecting thermal noise signals as physical entropy sources, and calculating the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method, and extracting the thermal noise entropy value; performing hashing on the thermal noise entropy value to generate a dynamic random seed, and performing mapping rule calculation based on the dynamic random seed and the preset heterogeneous execution body mapping strategy rules to obtain To the target execution body serial number; according to the target execution body serial number, build an isolated container instance through the container management interface at the edge node, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script; run the security verification script through the heterogeneous execution body in the isolated container instance, and judge the comprehensive credibility score based on the judgment threshold in the preset consistency decision mechanism to generate the vulnerability exploitable status; block and alarm the vulnerability exploitable status to form a preliminary security disposal record, and summarize the disposal action and verification process information in the preliminary security disposal record and the verification result set to generate an audit log covering the entire process.

[0008] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification of the present invention, the specific steps of generating suspicious event alarm data are as follows:

[0009] Collect real-time network communication traffic, host logs, and user behavior information to generate real-time network security monitoring raw data, and perform format normalization to generate a structured monitoring feature data set;

[0010] Match structured monitoring feature data sets with predefined attack behavior rules to identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data.

[0011] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification of the present invention, the specific steps of extracting the thermal noise entropy value are as follows:

[0012] Based on the suspicious event alarm data, the physical entropy source chip of the target terminal is activated to collect thermal noise signals;

[0013] The thermal noise signal is filtered and denoised, and the random walk modeling method is used to convert the thermal noise signal after filtering and denoising into a Brownian motion trajectory time series;

[0014] By using the Brownian motion trajectory modeling method, the fluctuation parameters of the Brownian motion trajectory time series are calculated and the thermal noise entropy value is extracted.

[0015] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification of the present invention, wherein: the target execution body serial number is obtained, the specific steps are as follows:

[0016] The thermal noise entropy value is calculated using a hash function to generate an initial hash value, which is then subjected to secondary perturbation processing to obtain a dynamic random seed.

[0017] According to the dynamic random seed, combined with the preset heterogeneous executable mapping strategy rules, a weighted round-robin scheduling algorithm is used to calculate the mapping rules and obtain the target executable sequence number.

[0018] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification of the present invention, the specific steps of obtaining the security verification script are as follows:

[0019] Use feature extraction algorithms to extract vulnerability feature parameters from suspicious event alert data;

[0020] Match the corresponding vulnerability numbers in the vulnerability number database using vulnerability feature parameters to generate a vulnerability number list;

[0021] Based on the target executable serial number, an isolated container instance is built on the edge node through the container management interface.

[0022] Input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the corresponding security verification script.

[0023] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification of the present invention, wherein: the specific steps of generating the vulnerability exploitable state are as follows:

[0024] Distribute the security verification script to multiple heterogeneous execution bodies within the isolated container instance, run the security verification scripts separately, generate verification result data, and aggregate the verification result data of multiple heterogeneous execution bodies to form a verification result set;

[0025] Based on the statistical characteristics of the verification result set, through threshold setting, voting mechanism design and anomaly detection method, the judgment threshold, voting rules and anomaly elimination strategy are set to form a consistent decision-making mechanism;

[0026] According to the voting rules and anomaly rejection strategy in the consistency decision-making mechanism, the verification result set is weighted and statistically integrated to obtain a comprehensive credibility score;

[0027] Based on the judgment threshold in the consistency decision mechanism, the comprehensive credibility score is judged to generate the vulnerability exploitability status.

[0028] As a preferred solution of the network security monitoring method based on dynamic vulnerability verification of the present invention, the specific steps of generating an audit log covering the entire process are as follows:

[0029] Taking the vulnerability exploitability status as input, it matches the predefined security policy rule base, identifies the corresponding blocking and alarm operation instructions, and forms a preliminary security disposal record;

[0030] Summarize the disposal actions and verification process information in the preliminary security disposal records and verification result sets to generate an audit log covering the entire process.

[0031] In the second aspect, the present invention provides a network security monitoring system based on dynamic vulnerability verification, including a real-time monitoring module, an entropy value extraction module, a seed generation module, a container construction module, a verification execution module and a security disposal module; the real-time monitoring module is used to collect real-time network security monitoring raw data, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data; the entropy value extraction module is used to collect thermal noise signals as physical entropy sources based on suspicious event alarm data, and calculate the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method, and extract the thermal noise entropy value; the seed generation module is used to perform hash processing on the thermal noise entropy value to generate a dynamic random seed, and based on the dynamic random seed and the preset abnormal operation event, generate a dynamic random seed. Construct the execution body mapping policy rules, calculate the mapping rules, and obtain the target execution body serial number; the container construction module is used to construct an isolated container instance through the container management interface at the edge node according to the target execution body serial number, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script; the verification execution module is used to run the security verification script through the heterogeneous execution body in the isolated container instance, and judge the comprehensive credibility score based on the judgment threshold in the preset consistency decision mechanism to generate the vulnerability exploitable status; the security disposal module is used to block and alarm the vulnerability exploitable status, form a preliminary security disposal record, and summarize the disposal action and verification process information in the preliminary security disposal record and the verification result set to generate an audit log covering the entire process.

[0032] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the network security monitoring method based on dynamic vulnerability verification as described in the first aspect of the present invention is implemented.

[0033] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the network security monitoring method based on dynamic vulnerability verification as described in the first aspect of the present invention.

[0034] The beneficial effects of this invention include: by generating a dynamic random seed based on thermal noise entropy and mapping the target executables using a weighted round-robin scheduling algorithm, dynamic and non-deterministic resource allocation is achieved during vulnerability verification, avoiding the attack prediction risks associated with fixed execution paths. This enhances the randomness and robustness of the verification process, effectively improving anti-circumvention capabilities and security in complex network environments, further ensuring the comprehensiveness and concealment of vulnerability verification, and improving the flexible responsiveness and scheduling efficiency of heterogeneous executable scheduling strategies in changing task environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0036] Figure 1 This is a flow chart of the network security monitoring method based on dynamic vulnerability verification in the present invention.

[0037] Figure 2 Schematic diagram of a network security monitoring system based on dynamic vulnerability verification in the present invention.

[0038] Figure 3 This is a flow chart of thermal noise entropy value extraction in the present invention.

[0039] Figure 4 Flowchart generated for the exploitable state of the vulnerability in the present invention. DETAILED DESCRIPTION

[0040] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0041] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0042] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.

[0043] Reference Figures 1 to 4 , is an embodiment of the present invention, which provides a file encryption method, comprising the following steps:

[0044] S1. Collect real-time network security monitoring raw data, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data.

[0045] S1.1. Collect real-time network communication traffic, host logs, and user behavior information to generate real-time network security monitoring raw data, and perform format normalization to generate a structured monitoring feature data set.

[0046] Specifically, it collects real-time network communication traffic data, including network packet header information and transmission content, collects host log data, covering operation events, process activities and error records, and collects user behavior information, such as login and logout records and operation instruction sequences; parses and cleans according to a unified data format, and removes invalid fields and abnormal values; normalizes the format of the cleaned real-time network security monitoring raw data according to the preset field mapping rules, and converts it into a standardized real-time network security monitoring raw data structure; extracts features from the real-time network security monitoring raw data after format normalization, and generates a structured monitoring feature data set, including traffic features, log features, and behavior features.

[0047] S1.2. Match the structured monitoring feature data set with predefined attack behavior rules to identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data.

[0048] Specifically, relevant features are extracted from each feature sample data in the structured monitoring feature data set, and then compared with each matching condition in the predefined attack behavior rules one by one. The specific comparison process is as follows: for each feature sample data in the structured monitoring feature data set, the network protocol field, host log field, and user operation field are extracted; and compared with the network protocol anomaly matching conditions, host behavior anomaly matching conditions, and user operation anomaly matching conditions defined in the attack behavior rule library respectively; when the network protocol field exceeds the protocol anomaly threshold obtained based on historical normal communication behavior statistics, the host log field meets the behavior anomaly pattern, or the user operation field hits the abnormal instruction sequence, the feature sample is marked as an abnormal operation event, and the abnormal event identification data is output. For the identified abnormal operation events, the abnormal alarm processing logic is further called to generate suspicious event alarm data containing the abnormal event type, trigger time, target host identification, and suspected user identification.

[0049] It should also be explained that predefined attack behavior rules include the establishment and maintenance of a rule base. Based on known attack characteristics and security threat intelligence, rule templates are developed, covering abnormal network traffic patterns, malicious instruction sequences, and abnormal permission operations. Matching conditions, matching thresholds, triggering thresholds, and priorities are then set for each rule in the rule base. Matching conditions are defined based on characteristic fields of typical attack behaviors, including specific protocol types, abnormal packet structure characteristics, or operational behavior patterns. Matching thresholds are set based on the statistical distribution of historical normal behavior data, such as the frequency range of field values ​​or the threshold for similarity between operational sequences. Triggering thresholds are set based on security incident response strategies, generally determined by the number of consecutive hits or an upper limit on the probability of a hit. Priorities are graded based on the severity level, propagation speed, and historical trigger frequency of the vulnerability associated with the rule. The rule base is regularly updated and optimized to adapt to new attacks. During the application of the rule base, the structured monitoring feature dataset is compared item by item with the matching conditions of each rule in the rule base. The degree of match and matching threshold determine whether an abnormal event is triggered, thereby accurately identifying potential attack behaviors.

[0050] S2. Based on the suspicious event alarm data, the thermal noise signal is collected as the physical entropy source, and the fluctuation parameters of the Brownian motion trajectory time series are calculated through the Brownian motion trajectory modeling method to extract the thermal noise entropy value.

[0051] S2.1. Based on the suspicious event alarm data, activate the physical entropy source chip of the target terminal to collect thermal noise signals.

[0052] Specifically, the target terminal identification parameters are extracted from the suspicious event alarm data and the target terminal physical address information is parsed; then a remote activation command is sent to the control interface of the physical entropy source chip of the target terminal to start the physical entropy source chip to enter the working state; the physical entropy source chip continuously collects the thermal noise voltage signal generated by the internal thermistor in the activated state, and the sampling frequency and sampling duration are set according to the event level parameters contained in the suspicious event alarm data. For example, when the event level parameter is high, the sampling frequency is 10kHz and the sampling duration is 5 seconds; after the acquisition is completed, the thermal noise voltage signal is buffered and stored in the form of a time series, and the thermal noise signal is output for subsequent processing.

[0053] S2.2. Filter and de-noise the thermal noise signal, and use the random walk modeling method to convert the filtered and de-noised thermal noise signal into a Brownian motion trajectory time series.

[0054] Specifically, a bandpass filter method was used to perform preliminary filtering on the thermal noise signal data, with the filter passband set to 100Hz to 10kHz to remove low-frequency drift components and high-frequency spike interference. Wavelet denoising was then used to refine the filtered thermal noise signal data. The Daubechies wavelet basis function was selected and the number of decomposition layers was set to three. Signal decomposition, threshold denoising, and reconstruction were performed to obtain the denoised thermal noise signal data. The denoised thermal noise signal data was then used as input and transformed using a random walk modeling method. Specifically, the initial position was set to zero, the thermal noise voltage value corresponding to each time step was considered the current position increment, and the values ​​were accumulated sequentially in time series order to construct a Brownian motion trajectory time series.

[0055] It should also be explained that the specific steps for performing signal decomposition, threshold denoising and reconstruction operations are as follows: performing wavelet decomposition on the thermal noise signal data after bandpass filtering, selecting the Daubechies wavelet basis function, and splitting the signal into approximation coefficients and detail coefficients at multiple scales according to the set three-layer decomposition level; denoising the detail coefficients of each layer according to the denoising rules, setting the low-amplitude coefficients to zero or reducing them to suppress high-frequency noise components; synthesizing the processed approximation coefficients and the denoised detail coefficients into a time domain signal through the wavelet reconstruction method, and outputting the denoised thermal noise signal data.

[0056] S2.3. By using the Brownian motion trajectory modeling method, the fluctuation parameters of the Brownian motion trajectory time series are calculated, and the thermal noise entropy value is extracted.

[0057] Specifically, the Brownian motion trajectory time series is subjected to a differential operation at equally spaced time steps to obtain the amplitude change values ​​between adjacent time points and obtain a differential amplitude sequence. The arithmetic mean formula and the unbiased sample standard deviation calculation formula in the statistical analysis method are used to calculate the mean and standard deviation of the differential amplitude sequence, respectively, to construct a fluctuation amplitude distribution sequence. Then, a sliding window segmented statistics is performed based on each fluctuation amplitude sequence, and the sliding window variance estimation method is used to calculate the variance of the differential value within each sliding window of a fixed length to obtain a variance value reflecting the change in local fluctuation intensity. Subsequently, the variance value sequence is normalized to form a probability distribution function. Based on the probability distribution function, the thermal noise entropy value is calculated, and the expression is:

[0058] ;

[0059] in, represents the thermal noise entropy value, Indicates the thermal noise amplitude level The probability of appearing in the Brownian motion trajectory time series, express The logarithm of Indicates the thermal noise amplitude level.

[0060] S3. Hash the thermal noise entropy value to generate a dynamic random seed, and perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous executable mapping strategy rule to obtain the target executable serial number.

[0061] S3.1. Use a hash function to calculate the thermal noise entropy value to generate an initial hash value, and perform a secondary perturbation process to obtain a dynamic random seed.

[0062] Specifically, the thermal noise entropy value is numerically normalized and converted into a fixed-length binary representation; then, an existing hash function, such as the SHA-256 hash function, is used to perform a hash operation on the binary representation to generate an initial hash value; then, the initial hash value is used as input and concatenated and encoded with the current timestamp parameter and the event level parameter to generate a perturbation input string; then, a second hash operation is performed on the perturbation input string, and the perturbed hash result is output as a dynamic random seed.

[0063] S3.2. Based on the dynamic random seed and the preset heterogeneous executable mapping strategy rules, a weighted round-robin scheduling algorithm is used to calculate the mapping rules and obtain the target executable sequence number.

[0064] Specifically, the preset heterogeneous executor mapping strategy rules in the task scheduling configuration are parsed, where heterogeneous executors include edge nodes, fog computing nodes, and cloud computing nodes, which respectively come from the edge device cluster, local intermediate computing nodes, and remote cloud resource pool in the IoT layered architecture; the performance weight parameters and current load status parameters corresponding to each heterogeneous executor are extracted. The performance weight parameters are constant values ​​predefined based on static indicators such as hardware processing power, network bandwidth, and response delay, while the current load status parameters are calculated based on the task queue length and average task processing delay collected in real time; then a weighted round-robin scheduling algorithm is adopted, with a dynamic random seed as the initial offset, to traverse all heterogeneous executors in sequence, and the performance weight parameters and current load status parameters of each executor are combined to generate a corresponding weighted score value, and a scheduling candidate sequence is constructed; finally, the corresponding target position is determined based on the modulo calculation result of the scheduling candidate sequence and the dynamic random seed, and the heterogeneous executor at the target position is selected as the target executor sequence number of the current task.

[0065] The specific steps of the preset heterogeneous executor mapping strategy rules should also be explained: divide the edge nodes, fog computing nodes and cloud computing nodes according to the Internet of Things architecture, and set performance weight parameters for each of them; set the collection method and calculation rules of load status parameters, such as the real-time monitoring method of task queue length and processing delay; clarify the combination calculation formula and priority sorting rules of weight parameters in the mapping strategy; define the input parameter format required by the scheduling algorithm and the application method of dynamic random seeds; regularly update the mapping strategy rules to reflect the performance changes and load dynamics of heterogeneous executors to ensure the accuracy and real-time performance of the mapping rules.

[0066] S4. Based on the target executable serial number, an isolated container instance is constructed at the edge node through the container management interface. The vulnerability number list is input into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script.

[0067] S4.1. Use feature extraction algorithm to extract vulnerability feature parameters from suspicious event alarm data.

[0068] Specifically, the original field data containing vulnerability-related information is read from the suspicious event alarm data; then, a feature extraction algorithm is used to extract parameters such as vulnerability type, attack source address, attack timestamp, and attack payload characteristics in sequence according to the preset fields and formats of the vulnerability feature parameters; the extracted parameters are format converted and normalized to ensure that the vulnerability feature data structure meets the requirements of subsequent analysis; the processed vulnerability feature parameters are encapsulated in a predetermined format to form a structured vulnerability feature parameter set, thereby completing the extraction of vulnerability feature parameters.

[0069] S4.2. Use vulnerability feature parameters to match corresponding vulnerability numbers in the vulnerability number database and generate a vulnerability number list.

[0070] Specifically, based on the key fields in the vulnerability feature parameters, such as vulnerability type, attack payload characteristics and timestamp, the vulnerability number database is accessed. The vulnerability number database comes from the public vulnerability library and security vendor update data, and the vulnerability feature parameters are compared with the records in the vulnerability number database one by one according to the matching rules; during the comparison process, the consistency and similarity of the feature fields are judged according to the preset field matching threshold. If the preset matching conditions are met, the corresponding vulnerability number is extracted and recorded; if the matching conditions are not met, the vulnerability feature parameters are marked as "unidentified state" and the current vulnerability number database record is skipped, and the next vulnerability number database information is matched; the matching operation is repeated until the comparison query of all vulnerability feature parameters is completed; finally, all successfully matched vulnerability numbers are summarized in order to generate a vulnerability number list.

[0071] The specific steps of the preset field matching threshold should also be explained: according to the type of key fields in the vulnerability number database, enumeration type fields are judged by equality, text type fields are judged by calculating the edit distance for similarity, and time type fields are compared to see if the time difference is within the allowable range; the judgment result is compared with the field matching threshold, and those that meet the field matching threshold conditions are considered to be a successful match, and those that do not meet the conditions are considered to be a failed match; based on the matching result, decide whether to extract the corresponding vulnerability number.

[0072] S4.3. Based on the target execution body serial number, an isolated container instance is constructed at the edge node through the container management interface.

[0073] Specifically, according to the target executable serial number, a build request is sent through the container management interface, and the container image version and running configuration parameters corresponding to the target executable serial number are selected, such as CPU resources of 2 cores and memory resources of 4GB, to create an isolated container instance; after the container management interface receives the build request, it calls the container engine to initialize the isolated container instance, including mounting the file system, allocating network resources and configuring security policies; after the initialization is completed, the isolated container instance is started, and the instance identifier and running status information are returned to complete the construction process of the isolated container instance.

[0074] S4.4. Input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the corresponding security verification script.

[0075] Specifically, a list of vulnerability numbers is used as input, and a scheduling request is sent through the scheduling mechanism interface of the isolated container instance. The scheduling mechanism matches the vulnerability number list item by item with the corresponding security verification script identifier according to the pre-set vulnerability security verification script mapping rules. The vulnerability security verification script mapping rules are established based on historical vulnerability verification experience and the vulnerability type and applicable scope of the security verification script. The vulnerability security verification script mapping rules include the association between the vulnerability category and the corresponding verification script, the verification script priority and compatibility requirements;

[0076] The specific steps for screening security verification scripts are as follows: read each vulnerability number in the vulnerability number list, parse it one by one, and perform a one-to-one matching operation based on the correspondence between the vulnerability number and the security verification script identifier established in the locally deployed mapping database; for the records with successful matching, extract the corresponding security verification script identifier and summarize it to form a security verification script identifier; then, based on the security verification script identifier, load the corresponding script content from the locally maintained security verification script resource library, and finally generate a security verification script for vulnerability verification.

[0077] S5. Run the security verification script by isolating the heterogeneous executors in the container instance, and determine the comprehensive credibility score based on the judgment threshold in the preset consistency decision mechanism to generate the vulnerability exploitability status.

[0078] S5.1. Distribute the security verification script to multiple heterogeneous execution bodies within the isolated container instance, and run the security verification script separately to generate verification result data. The verification result data of multiple heterogeneous execution bodies are aggregated to form a verification result set.

[0079] Specifically, the security verification script to be distributed is sent to each heterogeneous executor in turn through the scheduling communication interface inside the isolated container instance; then the corresponding security verification script execution engine is called in each heterogeneous executor, the execution command is parsed according to the security verification script definition format, and the running process is started; during the running of the security verification script, the security verification script execution status, system response data, return information and abnormal log information are collected in real time to form the verification result data; after all heterogeneous executors complete the running of the security verification script, the internal scheduling mechanism of the isolated container instance will number and identify the verification result data corresponding to each heterogeneous executor, and output it to form the final verification result set.

[0080] S5.2. Based on the statistical characteristics of the verification result set, through threshold setting, voting mechanism design and anomaly detection method, the judgment threshold, voting rules and anomaly elimination strategy are set to form a consistent decision-making mechanism.

[0081] Specifically, based on the verification result set, the hit status value, response time value and error code value in each group of verification result data are extracted to form the statistical characteristics of the verification result set; based on the frequency distribution and security requirements of the hit status value in the verification result set, combined with empirical data and business scenarios, the judgment threshold is set, for example, setting a hit rate of more than 70% as a high confidence judgment threshold; then construct a voting rule, adopt a majority voting mechanism, and count the values ​​with the largest proportion in the hit status value and output it as a collective judgment, for example, the majority voting rule is set to more than half, which means consensus; for the response time value and error code value, an anomaly detection method based on the box plot method is adopted to eliminate outlier data falling outside the upper and lower quartiles to form an anomaly rejection strategy; finally, the judgment threshold, voting rules and anomaly rejection strategy are integrated to construct a consistency decision-making mechanism for verification result set decision-making.

[0082] S5.3. Based on the voting rules and anomaly rejection strategy in the consistency decision-making mechanism, perform weighted statistics and result fusion on the verification result set to obtain a comprehensive credibility score.

[0083] Specifically, each set of verification result data in the verification result set is preliminarily screened according to the anomaly rejection strategy set in the consistency decision mechanism, and outliers falling outside the upper and lower quartiles of the response time value and the error code value are removed; according to the voting rules set in the consistency decision mechanism, the number of occurrences of each hit status value in the remaining verification results is counted, and the proportion of the hit status value is calculated as the basic weight, which is expressed as follows:

[0084] ;

[0085] in, Indicates the The proportion of class hit status values, Indicates the The number of times the class hit status value appears in the remaining verification results, Indicates the total number of hit status values ​​in the remaining verification results. The index indicating the hit status;

[0086] The inverse of the response time value is used as the performance stability weight item, and the statistical results of each hit status value are weighted accordingly; the weighted statistical results are mapped to the [0,1] interval using the linear normalization method to form a preliminary credibility value; finally, the preliminary credibility value and the anomaly-free ratio of the error code value are weighted and fused, for example, superimposed at a ratio of 0.7 and 0.3 to obtain a comprehensive credibility score.

[0087] S5.4. Based on the determination threshold in the consistency decision mechanism, the comprehensive credibility score is determined to generate the vulnerability exploitability status.

[0088] Specifically, the comprehensive credibility score is compared with the judgment threshold; if the comprehensive credibility score is greater than or equal to the judgment threshold, the vulnerability is judged to be in an "exploitable" state; if the comprehensive credibility score is less than the judgment threshold, the vulnerability is judged to be in an "unexploitable" state; for example, if the judgment threshold is set to 0.8, when the comprehensive credibility score is 0.85, the vulnerability is judged to be in an "exploitable" state; if the comprehensive credibility score is 0.75, the vulnerability is judged to be in an "unexploitable" state; finally, the corresponding vulnerability exploitable state is generated according to the judgment result.

[0089] S6. Block and issue alerts on the exploitable state of the vulnerability to form a preliminary security disposal record. Summarize the disposal actions and verification process information in the preliminary security disposal record and verification result set to generate an audit log covering the entire process.

[0090] S6.1. Take the vulnerability exploitable status as input, match it with the predefined security policy rule base, identify the corresponding blocking and alarm operation instructions, and form a preliminary security disposal record.

[0091] Specifically, the vulnerability exploitable status is used as input, and each rule item in the predefined security policy rule base is read, including the correspondence between the vulnerability exploitable status and the blocking operation instructions and the alarm operation instructions; the vulnerability exploitable status is compared one by one with the vulnerability status fields of all rule items in the predefined security policy rule base, and the rule items whose vulnerability exploitable status fields are completely consistent with the current input are screened out; the corresponding blocking operation instructions and alarm operation instructions are extracted from the successfully matched rule items; the vulnerability exploitable status, the matched blocking operation instructions and the alarm operation instructions are combined to generate a structured preliminary security disposal record.

[0092] The specific steps of the predefined security policy rule base should also be explained: set the structural fields of the rule base, including at least the vulnerability exploitable status field, the blocking operation instruction field and the alarm operation instruction field; based on previous security incident response records, collect representative vulnerability exploitation scenarios, and classify and identify each vulnerability exploitable status, such as "high-risk exploitable", "medium-risk suspected exploitable" or "low-risk unexploitable"; for each type of vulnerability exploitable status, determine the corresponding blocking operation instruction content, such as "interrupt process", "block IP", "disable port", etc., and the alarm operation instruction content, such as "push email notification", "generate audit log" and "trigger sound and light alarm", etc.; organize the three types of field contents into rule items in a one-to-one correspondence and store them in the predefined security policy rule base; verify the constructed rule items to ensure that the content of the vulnerability exploitable status field is unique and that each item contains complete blocking operation instruction and alarm operation instruction fields.

[0093] S6.2. Summarize the disposal actions and verification process information in the preliminary security disposal records and verification result set to generate an audit log covering the entire process.

[0094] Specifically, the multi-source heterogeneous data fusion and time series correlation analysis method is adopted to extract the timestamp, type and execution result information of the disposal action from the security disposal record, and at the same time extract the timestamp, steps and corresponding result information of the verification process from the verification result set, and sort them according to the timestamp to form a unified time series data; based on the time series correlation analysis method, the time dependency and triggering sequence between the disposal action and the verification process are calculated, and abnormal time series data are eliminated; the fused time series data is generated according to the preset log format to generate an audit log covering the entire process of vulnerability detection, verification and disposal.

[0095] The present embodiment also provides a network security monitoring system based on dynamic vulnerability verification, including: a real-time monitoring module, an entropy value extraction module, a seed generation module, a container construction module, a verification execution module and a security disposal module; the real-time monitoring module is used to collect real-time network security monitoring raw data, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data; the entropy value extraction module is used to collect thermal noise signals as physical entropy sources based on suspicious event alarm data, and calculate the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method, and extract the thermal noise entropy value; the seed generation module is used to perform hash processing on the thermal noise entropy value to generate a dynamic random seed, and based on the dynamic random seed and the preset heterogeneous execution module, generate a dynamic random seed. The row body mapping policy rules are used to calculate the mapping rules and obtain the target execution body serial number; the container construction module is used to build an isolated container instance through the container management interface at the edge node according to the target execution body serial number, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script; the verification execution module is used to run the security verification script through the heterogeneous execution body in the isolated container instance, and based on the judgment threshold in the preset consistency decision mechanism, the comprehensive credibility score is judged to generate the vulnerability exploitable status; the security disposal module is used to block and alarm the vulnerability exploitable status, form a preliminary security disposal record, and summarize the disposal action and verification process information in the preliminary security disposal record and the verification result set to generate an audit log covering the entire process.

[0096] This embodiment also provides a computer device, which is suitable for the network security monitoring method based on dynamic vulnerability verification, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the network security monitoring method based on dynamic vulnerability verification proposed in the above embodiment.

[0097] The computer device may be a terminal, comprising a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores an operating system and computer programs. The internal memory provides an environment for the operating system and computer programs stored in the non-volatile storage media. The communication interface of the computer device is used to communicate with external terminals via wired or wireless communication. Wireless communication may be achieved via Wi-Fi, a carrier network, NFC (near-field communication), or other technologies. The display of the computer device may be a liquid crystal display or an electronic ink display. The input device may be a touchscreen overlay on the display, buttons, a trackball, or a touchpad on the computer device housing, or an external keyboard, touchpad, or mouse.

[0098] This embodiment also provides a storage medium having a computer program stored thereon, which, when executed by a processor, implements the network security monitoring method based on dynamic vulnerability verification proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0099] In summary, this invention achieves dynamic and non-deterministic resource allocation during vulnerability verification by generating a dynamic random seed based on thermal noise entropy and mapping the target executables using a weighted round-robin scheduling algorithm, thereby avoiding the attack prediction risks associated with fixed execution paths. This enhances the randomness and robustness of the verification process, effectively improving anti-circumvention capabilities and security in complex network environments, further ensuring the comprehensiveness and confidentiality of vulnerability verification, and improving the flexible responsiveness and scheduling efficiency of heterogeneous executable scheduling strategies in changing task environments.

[0100] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A network security monitoring method based on dynamic vulnerability verification, characterized by: include, Collect real-time network security monitoring raw data, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data; Based on suspicious event alarm data, thermal noise signals are collected as physical entropy sources. The Brownian motion trajectory modeling method is used to calculate the fluctuation parameters of the Brownian motion trajectory time series and extract the thermal noise entropy value. Perform hashing on the thermal noise entropy value to generate a dynamic random seed, and perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous executable mapping strategy rules to obtain the target executable serial number; Based on the target executable serial number, an isolated container instance is constructed on the edge node through the container management interface. The vulnerability number list is input into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script. By running security verification scripts on heterogeneous executables within isolated container instances, the system determines the comprehensive credibility score based on the threshold in the preset consistency decision mechanism and generates the vulnerability exploitability status. Block and issue alarms on the exploitable state of vulnerabilities to form a preliminary security disposal record, and summarize the disposal actions and verification process information in the preliminary security disposal record and verification result set to generate an audit log covering the entire process.

2. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps of generating suspicious event alarm data are as follows: Collect real-time network communication traffic, host logs, and user behavior information to generate real-time network security monitoring raw data, and perform format normalization to generate a structured monitoring feature data set; Match structured monitoring feature data sets with predefined attack behavior rules to identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data.

3. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps of extracting the thermal noise entropy value are as follows: Based on the suspicious event alarm data, the physical entropy source chip of the target terminal is activated to collect thermal noise signals; The thermal noise signal is filtered and denoised, and the random walk modeling method is used to convert the thermal noise signal after filtering and denoising into a Brownian motion trajectory time series; By using the Brownian motion trajectory modeling method, the fluctuation parameters of the Brownian motion trajectory time series are calculated and the thermal noise entropy value is extracted.

4. The network security monitoring method based on dynamic vulnerability verification according to claim 1, wherein: The specific steps for obtaining the target executable serial number are as follows: The thermal noise entropy value is calculated using a hash function to generate an initial hash value, which is then subjected to secondary perturbation processing to obtain a dynamic random seed. According to the dynamic random seed, combined with the preset heterogeneous executable mapping strategy rules, a weighted round-robin scheduling algorithm is used to calculate the mapping rules and obtain the target executable sequence number.

5. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for obtaining the security verification script are as follows: Use feature extraction algorithms to extract vulnerability feature parameters from suspicious event alert data; Match the corresponding vulnerability numbers in the vulnerability number database using vulnerability feature parameters to generate a vulnerability number list; Based on the target executable serial number, an isolated container instance is built on the edge node through the container management interface. Input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the corresponding security verification script.

6. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for generating the exploitable state of the vulnerability are as follows: Distribute the security verification script to multiple heterogeneous execution bodies within the isolated container instance, run the security verification scripts separately, generate verification result data, and aggregate the verification result data of multiple heterogeneous execution bodies to form a verification result set; Based on the statistical characteristics of the verification result set, through threshold setting, voting mechanism design and anomaly detection method, the judgment threshold, voting rules and anomaly elimination strategy are set to form a consistent decision-making mechanism; According to the voting rules and anomaly rejection strategy in the consistency decision-making mechanism, the verification result set is weighted and statistically integrated to obtain a comprehensive credibility score; Based on the judgment threshold in the consistency decision mechanism, the comprehensive credibility score is judged to generate the vulnerability exploitability status.

7. The network security monitoring method based on dynamic vulnerability verification according to claim 1, characterized in that: The specific steps for generating an audit log covering the entire process are as follows: Taking the vulnerability exploitability status as input, it matches the predefined security policy rule base, identifies the corresponding blocking and alarm operation instructions, and forms a preliminary security disposal record; Summarize the disposal actions and verification process information in the preliminary security disposal records and verification result sets to generate an audit log covering the entire process.

8. A network security monitoring system based on dynamic vulnerability verification, based on the network security monitoring method based on dynamic vulnerability verification according to any one of claims 1 to 7, characterized in that: Including real-time monitoring module, entropy extraction module, seed generation module, container construction module, verification execution module and security disposal module; Real-time monitoring module, which is used to collect real-time network security monitoring raw data, detect abnormal operations through predefined attack behavior rules, identify potential abnormal operation events, trigger alarm logic and generate suspicious event alarm data; The entropy value extraction module is used to collect thermal noise signals as physical entropy sources based on suspicious event alarm data, calculate the fluctuation parameters of the Brownian motion trajectory time series through the Brownian motion trajectory modeling method, and extract the thermal noise entropy value; A seed generation module is used to perform hashing on the thermal noise entropy value to generate a dynamic random seed, and to perform mapping rule calculation based on the dynamic random seed and the preset heterogeneous executable mapping strategy rule to obtain the target executable sequence number; The container construction module is used to build an isolated container instance on the edge node through the container management interface based on the target executable serial number, and input the vulnerability number list into the scheduling mechanism of the isolated container instance for screening to obtain the security verification script; The verification execution module is used to run the security verification script through the heterogeneous executable body in the isolated container instance, and determine the comprehensive credibility score based on the judgment threshold in the preset consistency decision mechanism to generate the vulnerability exploitability status; The security disposal module is used to block and issue alarms on the exploitable status of vulnerabilities, form preliminary security disposal records, and summarize the disposal actions and verification process information in the preliminary security disposal records and verification result sets to generate an audit log covering the entire process.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network security monitoring method based on dynamic vulnerability verification according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security monitoring method based on dynamic vulnerability verification according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Security monitoring alarm device and method for network security vulnerabilities

    CN120074857A

  • Network security event vulnerability detection method and system

    CN120090851A